exceljs-hardened 版本在 5.0.0 之前,未能对写入 CSV 输出内容的单元格值中的前导等号(=)、加号(+)、减号(-)或 at 符号(@)进行中和处理。攻击者若能够影响导出的单元格值,便可注入可在电子表格应用程序中打开 CSV 文件时执行的公式,从而可能导致数据外泄或其他恶意行为。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-78207 | 9.4 CRITICAL | exceljs through 4.4.0 Prototype Pollution via deepMerge Reached From Note Serialization |
| CVE-2026-78206 | 7.5 HIGH | exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression |
| CVE-2026-78208 | 7.5 HIGH | exceljs through 4.4.0 Path Traversal via Unvalidated addImage filename |
No comments yet